Skip to main content
Cyber Health Score
Get started

Trust

Security and Trust

Cyber Health Score is designed around multi-tenancy, organisation isolation, role-based access, audited support access, fail-closed commercial and assessment controls, and durable processing separated from ephemeral coordination. This page summarises public-safe principles. It is not an auditor-ready attestation and does not claim ISO, SOC 2, Cyber Essentials, or penetration-test certification.

Product boundaries

What CHS does, and what it does not do

Boundaries are kept explicit so procurement, security review and tenant expectations stay evidence-led.

Bounded external posture platform

Cyber Health Score supports External Attack Surface Management, Continuous Assessment, Exposure Priority, Change Intelligence, Brand Protection, Evidence Vault, Supplier Assurance and Authorised Validation within declared product boundaries.

Not penetration testing

Cyber Health Score is not a red-team platform, exploit framework, authenticated internal vulnerability scanner, or guarantee that every vulnerability will be found.

Not internet-wide scanning

Passive Monitoring starts from verified customer seeds and applies traversal bounds. It does not perform internet-wide scanning or unrestricted enumeration.

Not automatic active authority

Discovered hosts, CDN edges, SaaS providers and related observations do not silently inherit Continuous Assessment or Authorised Validation authority.

Not certification

Reports and Evidence Vault support audit preparation. They do not constitute ISO, SOC 2, Cyber Essentials, PCI DSS or penetration-test certification unless separately achieved and contracted.

Security principles

How trust is built into the product

Authentication and authorisation

Authentication uses secure session cookies configured for the hosted environment. Authorisation is membership and role based. Workspace administrators control who can invite users, configure assessment policy, and grant time-limited support access.

Multi-tenancy and organisation isolation

Tenant data is scoped server-side to the organisation. Customer inventory, findings, alerts, remediation, reports, and CHS Agent answers are organisation-bounded. Cross-tenant access is not part of the product model.

Passive Monitoring versus Continuous Assessment

Passive Monitoring and Attack Surface inventory intelligence do not silently grant Continuous Assessment authority. Continuous Assessment requires explicit customer consent and remains bounded. Discovered third-party, CDN, SaaS, hosting, and ASN observations are informational and do not inherit customer assessment consent. Observed external exposure chains describe evidence-backed relationship topology only and are not internal attack paths.

Outbound request protections

Authorised external assessment paths retain public-IP validation, redirect revalidation, and DNS-rebinding mitigations. Durable workers load persisted jobs and revalidate consent and authority at execution time.

Auditability and Evidence Vault

Material tenant and operator actions are designed to be auditable. Governance, Evidence Vault, and reporting support stakeholder-ready evidence without promising certification outcomes.

Data handling

Privacy and data handling

Cyber Health Score processes account, organisation, Attack Surface inventory, assessment, finding, remediation, reporting and support data needed to operate the service for your tenant.

Tenant data is organisation-scoped. Cross-tenant access is not part of the product model.

Support access is tenant-consented, scoped, time-bound, revocable and audited when used.

This overview is not a complete privacy notice or Data Processing Agreement. Contractual data-processing terms are provided separately for commercial customers.

Retention

Retention follows plan entitlements and contractual configuration where supported. Export-before-delete and approval-gated deletion pathways exist for responsible lifecycle management. Destructive deletion remains disabled by default.

Subprocessor transparency

Hosted deployments commonly rely on infrastructure and delivery providers for application hosting, database, email delivery, payments and durable job delivery. Exact subprocessors for a commercial engagement are confirmed in that engagement's documentation and may change with notice under contract.

Vulnerability disclosure

We welcome responsible reports of security issues in the Cyber Health Score application and related public services.

  • Provide enough detail to reproduce the issue, including affected URLs, approximate time and impact.
  • Do not access customer tenant data beyond what is required to demonstrate the issue.
  • Do not perform destructive testing, denial-of-service, social engineering of staff, or mass automated scanning against production.
  • Allow a reasonable remediation window before public disclosure.

Security and architecture FAQs

Does Cyber Health Score certify compliance?

No. Evidence Vault, reports and governance readiness support preparation and stakeholder communication. Certification claims require separate achievement and contractual confirmation.

How is tenant isolation enforced?

Server-side authorisation scopes customer inventory, findings, alerts, remediation, reports and CHS Agent answers to the organisation. Cross-tenant access is not part of the product model.

What is the difference between Passive Monitoring and Continuous Assessment?

Passive Monitoring expands Attack Surface visibility from approved passive sources after verification. Continuous Assessment performs bounded external posture checks only against authorised assets.

Does Supplier Assurance allow supplier scanning?

No. A commercial supplier relationship recorded in Supplier Assurance does not authorise Cyber Health Score to actively assess that supplier.

What is Authorised Validation?

Authorised Validation is an explicit, time-bound, target-specific and technique-specific authority control plane. Existing assessment consent never grants it. Live adversarial validation remains disabled unless separately authorised.

Where do I report a security issue or abuse?

Use the vulnerability disclosure guidance on the Security pages, or contact us with a security intent. For suspected abuse of the platform, use the abuse reporting page.

Questions? Contact us or read the Trust centre.

Trust centre